Skip to content

Advanced Configuration

Evidence: Advanced Configuration
Description: ESXi Advanced Configuration
Category: System
Platform: esxi
Short Name: advconf
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

ESXi advanced configuration settings control low-level hypervisor behavior, security policies, and system parameters. These settings can be modified to weaken security, enable backdoors, or alter logging behavior, making them valuable for detecting unauthorized system modifications.

This collector gathers structured data about advanced configuration.

FieldDescriptionExample
AccessTimeAccess Time2023-10-15 14:30:25+03:00
AccessCountAccess Count123
URLURLExample value
BrowserBrowserExample value
TitleTitleExample value
VisitDurationVisit DurationExample value
ReferrerReferrerExample value
TypedCountTyped Count123
IsHiddenIs Hiddentrue
TransitionTypeTransition TypeExample value
VisitIDVisit ID123
TransitionQualifiersTransition QualifiersExample value
UserUserExample value
ProfileProfileExample value
HistoryFilePathHistory File PathExample value

This collector parses the advanced configuration file containing key-value pairs of ESXi system settings, extracting configuration parameter names and their corresponding values as defined in the host’s advanced options.

Advanced configuration analysis reveals security policy changes, unauthorized parameter modifications, and potential indicators of compromise. Comparing settings against baselines helps detect malicious configuration changes, disabled security features, or altered logging that may hide attacker activities.